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IS. (Original) The computer program product of claim 14 wherein the p 
count ofhow many packets a data collector or gateway examines. 
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adjust the number of buckets as the number of buckets approaches a second threshold 
Claims 22-49 are canceled. 



50. {Previously Presented? The data collector of chum 21 wherein based on the second 
threshold, the buckets are divided into more buckets or combined into fewer buckets 
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compare the value accumulated in the bucket to a threshold that depends oh the number 

ofbuekets. 

57. (Previously Presented} The data collector of claim 21 wherein as a value of a 
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58. (Previously Presented.) The data collector of claim 21 wherein the vari able number of 
buckets dynamically adjusts the amount of traffic and number of flows monitored, so tha t the 
data collector is not vulnerable to a denial of service attack against us own resources. 
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65. Previously Presented) The method of claim 63 wherein varvins* the number of 
buckets comprises: 

comparing the number of buckets to a threshold number of buckets; 

determining whether the number of buckets should be divided into more buckets or 

change. 
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70, (Currently Amended) A. computer program product residing on a computer readable 
medium .for monitoring traffic flow in a monitor device disposed to receive network traffic , 
packets , the computer pro gra m product comprises instructions for causing the device to: 

produce statistics corresponding to a parameter of the traffic flow to trace a tbe source of 
an attack, with producing further comprising: 

map she traffic flow into a plurality of buckets; 

vary the number of buckets according to the amount of traffic and number of flows 
aeeertfefg to breakdown the traffic flow into different buckets; and 
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in t he b uc k e t . 10 identify a source of the attack . 

71, (Previously Presented) The computer program product of claim 70 wherein 
instructions to vary, vary the number of buckets so that the monitoring device is not vulnerable 
to DoS attacks against its own resources. 

72. (Previously Presented) The computer pro-gram product of claim 7fi wherein 
instructions to vary comprises instructions to: 

compare the number of buckets to a threshold number of buckets; 

determine whether the number of buckets should be divided into more buckets or 
combined into fewer buckets based on comparing the number of buckets to the threshold and as 
the number of buckets changes, the buckets have values derived from the buckets prior to the 
change. 

73. (Previously Presented) The computer program product of claim 70 further comprising 
instructions to: 

compare accumulated statistic values from the buckets to second threshold values to 
determine that an event is of significance. 
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